Live data from Hacker News

Ask HN: What's a security risk you think people should be more aware of?

news.ycombinator.com

1–10 of 21 posts

Ask HN: What's a security risk you think people should be more aware of?

#1
Here's mine: QR codes. They're a terrible idea, especially when there's no URL attached. They remove someone's ability to verify that yes, this is the correct site, and are easy to bypass - a scammer can literally just put a different QR code over the intended one, and ta-da! Done.

Re: Ask HN: What's a security risk you think people should be more aware of?

#3
The camera app shows you what URL the QR code is going to before you click it.

I don't think it's really much of a risk because an attacker has to not only go to a physical location and replace the QR code, but they need to make some kind of replacement website that looks genuine to fool someone.

It's actually harder to pull off than a credit card skimmer.

Example: QR codes at a restaurant, I need to put the QR codes on every single menu (how am I going to do that discreetly without visiting the restaurant multiple times?) and then I also have to create a functioning website that mimics the restaurant's website. And then what happens when the customer doesn't get any food when the order via QR code and the server doesn't see any order being placed? Everyone involved would be immediately suspicious.

Re: Ask HN: What's a security risk you think people should be more aware of?

#8
Your mobile provider stores your location data for 1 (Verizon), 2 (Tmobile), or 7 (AT&T) years. Tower dumps long term, granular advanced timing/ranging to within meters for ~90 days.

Don’t think too fondly of Verizon’s short retention schedule though, they sell your location to data brokers.

Re: Ask HN: What's a security risk you think people should be more aware of?

#9
Ambient Authority... it's the computer equivalent of giving the full electrical grid, unrestricted in any way, to every single outlet in your house. No fuses, circuit breakers, or other protection.

Yet this is the underlying design that Linux, Windows, MacOS are all based on.

We have ways to default to NO authority, and still make computers just as easy to use, but we don't do it. Because it would require reconfiguring everything, and porting a lot of code to new OSs.

Re: Ask HN: What's a security risk you think people should be more aware of?

#10

Boring one, but if you get a work email with bank account details be suspicious. Maybe book a face call before using such details and confirm them.

Now I have to unfortunately inform you that some company got scammed via AI video of some high level executing demanding money be transfered.
Post reply on HN